(navigation image)
Home Animation & Cartoons | Arts & Music | Community Video | Computers & Technology | Cultural & Academic Films | Ephemeral Films | Movies | News & Public Affairs | Prelinger Archives | Spirituality & Religion | Sports Videos | Television | Videogame Videos | Vlogs | Youth Media
Search: Advanced Search
Anonymous User (login or join us)
Upload

View movie

[item image]
View thumbnails

Play / Download (help[help])

(169.7 M)Ogg Video
(201.0 M)512Kb MPEG4
(375.1 M)MPEG4


All Files: HTTPS

Resources

Bookmark

Recon 2005 - Jonathan Levin - The Dark Side of Winsock (2005)

something has gone horribly wrong 8-p
Prefer flash? · Embed · Questions/Feedback?

The Winsock SPI, or Service Provider Interface, has been a part of Winsock since the advent of version 2.0. It enables providers to extend the Winsock API transparently, by installing their own hooks and chains to application API calls. However, its formidable capabilities are not put to widespread use... aside from spyware.
This lecture begins with a brief overview of the Windows TCP/IP Stack - reviewing the terminology, From NDIS to Winsock 2. We then delve further to explore Winsock, recapping the standard (Berkeley-Derived) API calls and their semantics.
Going "Under the Hood" of Winsock, we next explore the Service Provider Interface, and its potent use to extend (or spy on) the Winsock calls. We next show the unbearable lightness of intercepting DNS lookups and UDP/TCP based communication by a hidden DLL.
Finally, we conclude by trying to discuss countermeasures to this insidious channel.
Bio
Interested in Information Security since the mid '90's, Jonathan Levin has over 8 years of consulting experience, and has trained numerous IT and security related courses, in academic as well as technical fora. Jonathan first encountered the Winsock SPI back in '98 (and wrote a device driver over it...), and is surprised to see that even after almost 7 years it has gotten little attention, despite its formidable capabilities.


This movie is part of the collection: Community Video

Audio/Visual: sound, color
Keywords: Recon,Security,Conference,Winsock
Contact Information: www.recon.cx


Individual Files

Movie Files MPEG4 Ogg Video 512Kb MPEG4
recon2005_jonathan_levin_the_dark_side_of_winsock.avi 375.1 MB
169.7 MB
201.0 MB
Image Files Thumbnail Animated GIF
recon2005_jonathan_levin_the_dark_side_of_winsock.avi 6.4 KB
267.1 KB
Information FormatSize
Recon2005_Jonathan_Levin_files.xml Metadata [file]
Recon2005_Jonathan_Levin_meta.xml Metadata 2.0 KB

Be the first to write a review
Downloaded 598 times
Reviews


Terms of Use (10 Mar 2001)